The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882
https://github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183
https://github.com/braintree/sanitize-url/pull/40
https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11